CVE-2008-1475
Published Mar 24, 2008
Last updated 7 years ago
Overview
- Description
- The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:roundup-tracker:roundup:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE1D1977-97A0-4407-9767-D9E6D6F9F6AE", "versionEndIncluding": "1.4.3" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19ECB7A0-10A6-4745-A14A-1FDCBA54FA3E" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9968A3F6-095B-40E8-B5B3-FF0B9DDF4D66" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53AB2FBF-3D72-4548-B7EF-A9966DDADE99" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0079C51C-5341-4ABD-AEC3-ED95D6B3849E" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D942F581-EEE1-4475-91BC-A381F647DB4E" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85EA6E14-83A2-4EB5-B288-1BAAAE7BB15E" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B79CB12-0F99-4337-8FFE-300E1F2635A8" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D7924E0-09DE-4231-8543-93F132C525D3" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5181473-7735-4C4D-84EB-45123A4CB2EA" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "611D6B74-E98A-4060-A4E8-0066B23097C5" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDDDAB17-2E78-4F3A-8129-5F6B0AD6824C" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7BC05048-471F-43B8-84F1-B3A4AD0BEB1E" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D5EA1112-FD27-4560-99B9-F95CB4875B50" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B1C7A4E-B709-45B9-820B-9DA47D09A768" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.3.0:pre1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12248494-B69A-493A-8BAA-AED8B6D90967" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.3.0:pre2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83D18991-4357-4EDA-B58A-C2B2D55AF65C" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.3.0:pre3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3EA23543-A008-4A35-A2FD-A5C92419B5D4" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85911897-FF14-4287-A70C-2BE1533D7DD8" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.4.0:b1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5AF4647-28B7-4A1F-8CE0-1AECF5E9DA52" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.4.0:b2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7491CD5B-BE8B-43D9-9A9C-A9D9091FFF98" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C170F3BF-A954-4259-AFEA-8FBBA9A03E8C" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "368312AF-2FC0-4528-A735-FE8E6412637D" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.4.2:pr1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "15A83A5C-A463-4A90-9C2B-CD4BF64D9F93" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BFA22ED9-74AB-4B1A-AE32-002CBC70DD33" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CA7035B-ACAD-43CC-8B0A-5D5C71ED4D00" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5FF02B8B-EE0E-490C-B611-9E9073B08A16" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB0B1077-5E96-49D8-8C42-E1B269D977D2" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.0:pr1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "62D6C85E-EDA1-4F97-86F7-A55D0209E9E9" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "046CAABB-4A40-4734-9506-FE9E5D74ED6E" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3D7C743E-B264-4FEB-AE0D-6B63C6D25CD3" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "18AC89CD-2092-4694-8DA3-268466CB1728" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8EB5412-927B-49F4-B1F1-0890AB674F1D" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B52588E4-C6C4-45DE-B8C2-4948AEAA2E75" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C747D8A-1FD7-4E80-949F-49833D8A871B" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "74CEEC73-4AF9-4E5A-A526-101E23A7ED2F" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.8:stable:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6890C793-5346-4274-91F6-D3A1F4D4454B" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.5.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10F15818-1EC9-4E72-8E10-BF7CBEE6DECC" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2136129D-9795-4281-A07E-297BE50A7A93" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.0:b1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31430BEC-1190-46F9-82B8-6EBE6CBE1BEE" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.0:b2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0855645-97A3-4CA1-9A7C-3050151302E3" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.0:b3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86F1057A-0273-4B77-8DD9-32D54676F991" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.0:b4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ACC3C30E-4796-49CE-AFDF-DC7B29737FAB" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "068DEB7C-DAC2-45D6-A0B6-DC54EF52DF14" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "960311B7-4C1B-4D7F-B8D1-A99977C389D3" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "953F1AAF-CFF8-462C-99E4-7A4D8404BCEA" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "280DC837-EB0D-42EA-8236-FFD87B0987AB" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B57648C-D3D8-4ADE-8500-9E7CC170DF63" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E74C7F38-1DF5-4817-A6F7-F24E015346C0" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7305D65-2C60-4AC0-86E8-10A115EC008C" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8829C3BE-C384-4CB5-9128-12338E1E68F0" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "134F2504-202E-456E-973F-CDF26EC119A3" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67CB2FD7-7E9E-4395-98B9-7A97B2140A4F" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.6.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "932E8C5F-23DC-4A3D-8683-095E98595A06" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34318627-2740-4FDC-BF08-87CD6AD82F8B" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.0:b1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8455602A-65E5-4DAE-9D66-CA9A226E5AAB" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.0:b2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5ABA002F-3226-4492-9E4A-F8D2BD0C0791" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.0:b3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3595DB2B-EA69-4A47-B69D-3D526E9E9D89" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D864CE13-3E5D-4A43-B45C-50FD73634828" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5E6CF969-C90B-47AD-8538-F865C6D96F82" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE2ADB27-CC67-4E07-AB14-D4E7AFBAF41A" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C00B6823-DDC4-455B-806E-20DC50C91CBF" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25307B01-1BDF-402C-BAB8-3F79E3AD5FE3" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B20E4D7D-AEB3-431A-8EAD-AA0968F339A8" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE10C1E5-78C2-460D-BD73-97026C18D2D7" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EAA37A04-8B76-41F5-BB6A-BC510100A59A" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E83205C4-D7BE-41C8-B4B2-76B265743D39" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CAA29FD3-B9CE-47B8-9593-BD953C3ECC6F" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88EC7A4B-678F-4A87-9E7F-1F9B95647E6C" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.7.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7B45F23-702E-436A-BEF5-26AB0B7B3288" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "41C8C39E-F339-48A4-83AB-D89493070418" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.8.0:b1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C1E36E4-C4C9-4AE9-A91E-504B75441D9B" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.8.0:b2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA49A32F-5932-4E3D-80F4-3F695E6D967E" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D98E71AD-3B23-44D8-B7DE-902B616BED76" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36336002-7EDC-47D2-A652-923C5DC99847" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.8.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6893FFAD-A2D1-4C8B-983F-68C2899E56E3" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.8.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81944927-FFCF-4709-B80B-7279CE31A0D4" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.8.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A5B11756-4710-4E9A-9E37-C3FA1C5E5B7C" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.8.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8DEAB81E-DAA8-49CD-AEC7-1492DE605172" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:0.9.0:b1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AF05890-2633-4863-B545-ED923D9A4A00" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D00A7FA-8CC2-49DE-B515-7ADA3240549E" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55982C77-F866-4298-BD46-E3DF136C6203" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69A92DF0-153B-4130-A12F-28A921673A94" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5E6A5DC6-8E85-4545-840A-3D5DF8FB3B2C" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A85D14A2-5505-43CC-8416-6165C604D363" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BCEF97A-C493-41A8-8A7D-4A187F016AEB" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55B7551D-6264-4949-A038-6006F432F261" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12903A2D-44DF-4606-B4DB-0501786A22C3" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7032E7E5-B353-451C-AA8A-70F055DE68C9" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A11A4AFF-EE53-477D-9B82-6A65A6765DFE" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F5E2921-8219-4F59-B877-C2BCF9C0AB02" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0038D97D-E099-41FD-B467-C2FA8A1A04BD" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCFDDF8D-B34E-4A31-A335-E41477436C44" }, { "criteria": "cpe:2.3:a:roundup-tracker:roundup:1.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "764F3225-B6F0-497E-B2BD-A6CBA40D06BF" } ], "operator": "OR" } ] } ]